Junglewise Threat Intelligence

CVE-2026-46047: Linux Kernel use-after-free in QRTR nameservice driver remove callback

CVE-2026-46047 · Severity: info · CVSS 0 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Qualcomm IPC Router (QRTR) nameservice driver. This component manages communication between different processors on a device. A flaw during the driver's shutdown process could allow a system crash or unpredictable behavior if network data arrives at the exact moment the driver is being removed.

Technical details

A use-after-free (UAF) vulnerability exists in net/qrtr/ns.c within the Linux kernel. The issue occurs in the driver's remove callback: if a packet arrives after destroy_workqueue() is called but before sock_release(), the qrtr_ns_data_ready() callback attempts to queue work on the already destroyed workqueue. This leads to a dereference of a freed or invalid work struct. The fix involves restoring the default 'sk_data_ready' callback at the beginning of the removal process and ensuring RX threads complete before workqueue destruction. This vulnerability is primarily reachable during module unloading or system shutdown.

Affected products

  • Linux Linux Kernel versions prior to 6.9 (specifically affecting qrtr ns)

Timeline

  • 2026-04-09: other: Patch submitted by developer
  • 2026-05-27: advisory: CVE-2026-46047 published

References

Related threats